platform-models-api-configure
forcedotcom/sf-skills
Configure Claude Code or Claude Agent SDK to use Salesforce Models API with OrgJWT authentication.
What is platform-models-api-configure?
Set up an AI coding agent to route requests through the Salesforce Models API endpoint using signed OrgJWT tokens and Bedrock-mode authentication. Use this when configuring agent settings, API-key helpers, credentials, or troubleshooting 401/404 errors on the Models API.
- Generate and manage OrgJWT tokens via client_credentials OAuth flow
- Configure Bedrock-mode environment variables for Claude Code and Claude Agent SDK
- Set up JSON settings files with API-key helper scripts for agent authentication
- Verify Models API connectivity before applying configuration
- Diagnose and resolve authentication and model-availability errors
- Support both project-scoped and user-scoped agent settings
How to install platform-models-api-configure
npx skills add https://github.com/forcedotcom/sf-skills --skill platform-models-api-configure- Connected app in the Salesforce org with sfap_api OAuth scope and client_credentials flow enabled
- Consumer key and secret from the connected app
- curl (>=7.29.0) and jq (>=1.6.0) installed
- Salesforce CLI sf (>=2.0.0) installed
How to use platform-models-api-configure
- 1.Collect the org My Domain URL, connected-app consumer key/secret, target model name, and desired settings scope
- 2.Create .claude/.orgjwt.env with SF_INSTANCE_URL, SF_CLIENT_ID, and SF_CLIENT_SECRET; set permissions to 600 and add to .gitignore
- 3.Run the verification curl command to confirm the OrgJWT token and Models API endpoint return HTTP 200
- 4.Merge the settings.json configuration into .claude/settings.json with absolute paths for apiKeyHelper and correct environment variables
- 5.Fully restart the agent (e.g., restart Claude Code) so settings and API-key helper load at startup
Use cases
- Point Claude Code at Salesforce Models API for the first time with correct OrgJWT auth
- Troubleshoot 401 Unauthorized or 404 model-not-found errors on Models API calls
- Migrate an agent from standard Anthropic API to Salesforce Models API endpoint
- Document Models API setup as a runbook for team review before deployment
- Configure multiple agents or team members to use the same connected app credentials
- Salesforce developers setting up Agentforce with Claude Code
- DevOps engineers configuring AI agents for enterprise Salesforce orgs
- Technical leads documenting Models API setup for team onboarding
- Developers troubleshooting agent authentication against Salesforce endpoints
platform-models-api-configure FAQ
An OrgJWT is a signed JWT obtained via client_credentials OAuth flow with the sfap_api scope; it is valid for Models API calls. An sf org display token is an unsigned session token that will fail with 404 on the Models API. Always use the OrgJWT from the helper script, not the CLI session token.
ANTHROPIC_AUTH_TOKEN has higher precedence than apiKeyHelper. If it contains a value (e.g., a global Anthropic API key), the agent will use that token instead of calling the helper, bypassing the Models API and causing 401/404 errors.
Without this flag, Claude Code overwrites the Authorization header with AWS SigV4 credentials, replacing the OrgJWT. Setting it to 1 prevents that overwrite so the OrgJWT bearer token reaches the Models API.
No. This skill configures the agent to use an existing connected app. To create or configure the connected app, use the integration-connectivity-connected-app-configure skill instead.
Check that the connected app has the sfap_api scope and client_credentials flow enabled, the consumer key/secret are correct in .orgjwt.env, ANTHROPIC_AUTH_TOKEN is empty in settings.json, and the model name is a fully qualified sfdc_ai__… alias from the supported models list.
Full instructions (SKILL.md)
Source of truth, from forcedotcom/sf-skills.
name: platform-models-api-configure description: "Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT. Use this skill when pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1), setting up OrgJWT / Bedrock-mode auth, wiring the agent's settings, API-key helper, and credentials file for the Salesforce endpoint, or fixing Models API 401 / 404 / "model not available" errors. DO NOT TRIGGER when the user needs to create or configure the Salesforce Connected App itself (use integration-connectivity-connected-app-configure) or set up Named Credentials / callout auth (use integration-connectivity-generate)." metadata: cliTools: - tool: ["curl"] semver: ">=7.29.0" - tool: ["jq"] semver: ">=1.6.0" - tool: ["sf"] semver: ">=2.0.0" relatedSkills: - "integration-connectivity-connected-app-configure" - "integration-connectivity-generate" version: "1.0" domains: ["Platform", "Agentforce"]
Salesforce Models API setup for an AI coding agent
The Salesforce Models API (https://api.salesforce.com/ai/gpt/v1) is
authenticated with a signed OrgJWT (obtained via client_credentials with
the sfap_api scope — see scripts/get-orgjwt.sh; no proxy). That auth and the
base URL are the same for any agent. How each agent then talks to the
endpoint is agent-specific: Anthropic clients (Claude Code and the Claude
Agent SDK) route through Bedrock mode (the env vars in Step 3), whereas
other agents (e.g. Codex) use their own client config against the same endpoint
and token — Bedrock mode does not apply to them.
The steps below are the Claude Code / Claude Agent SDK reference implementation (Bedrock mode + a JSON settings file + an API-key helper). For a non-Bedrock agent, reuse the OrgJWT auth (Step 1) and the base URL, and apply the equivalent client settings in that agent's own config location instead of the Bedrock env vars.
Bundled scripts are in scripts/. Path placeholders below: <SKILL> = the
absolute path to this skill's own directory (the folder containing this
SKILL.md; resolve it from the skill path in context). <ABS> = the absolute
path to the user's project root. Always emit fully resolved absolute paths —
the API-key helper runs from an undefined working directory, so relative paths
break it.
Prerequisite
A connected app in the org with the sfap_api OAuth scope and the
client_credentials flow enabled (consumer key/secret + a run-as user).
Setup steps: https://developer.salesforce.com/docs/ai/agentforce/guide/access-models-api-with-rest.html
curl + jq installed.
Inputs to collect
SF_INSTANCE_URL— org My Domain, e.g.https://acme.my.salesforce.comSF_CLIENT_ID,SF_CLIENT_SECRET— connected-app consumer key/secret- Models API base URL:
https://api.salesforce.com/ai/gpt/v1 - Model: a fully qualified
sfdc_ai__…name, e.g.sfdc_ai__DefaultBedrockAnthropicClaude46Sonnet(full list: https://developer.salesforce.com/docs/ai/agentforce/guide/supported-models.html) - Scope: project (
<cwd>/.claude/settings.json, default) or user (~/.claude/settings.json) — reference-agent settings paths - Headers —
<FEAT>=x-client-feature-id(defaultai-platform-models-connected-app),<APP>=x-sfdc-app-context(defaultEinsteinGPT). Used in the Step 2 verify curl and inANTHROPIC_CUSTOM_HEADERS.
Steps (reference implementation)
Concrete values for a JSON-settings + API-key-helper agent. Reuse the OrgJWT auth, verify curl, and base URL verbatim for any agent; adapt the settings-file location and env-var wiring to the target agent.
- Write
<project>/.claude/.orgjwt.env(chmod 600), gitignore it:SF_INSTANCE_URL="..." SF_CLIENT_ID="..." SF_CLIENT_SECRET="..." - Verify — must return
200before writing settings:TOKEN=$(bash <SKILL>/scripts/get-orgjwt.sh <ABS>/.claude/.orgjwt.env) curl -s -o /dev/null -w '%{http_code}\n' \ <MODELS_API_URL>/model/<MODEL>/invoke-with-response-stream \ -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \ -H 'x-client-feature-id: <FEAT>' -H 'x-sfdc-app-context: <APP>' \ --data '{"anthropic_version":"bedrock-2023-05-31","max_tokens":16,"messages":[{"role":"user","content":"hi"}]}' - Write
.claude/settings.json(merge into existing; keep other keys):
Use absolute paths in{ "apiKeyHelper": "bash <SKILL>/scripts/get-orgjwt.sh <ABS>/.claude/.orgjwt.env", "model": "<MODEL>", "env": { "ANTHROPIC_AUTH_TOKEN": "", "CLAUDE_CODE_USE_BEDROCK": "1", "CLAUDE_CODE_SKIP_BEDROCK_AUTH": "1", "ANTHROPIC_BEDROCK_BASE_URL": "<MODELS_API_URL>", "ANTHROPIC_SMALL_FAST_MODEL": "<MODEL>", "ANTHROPIC_DEFAULT_MODEL": "<MODEL>", "ANTHROPIC_CUSTOM_HEADERS": "x-client-feature-id: <FEAT>\nx-sfdc-app-context: <APP>" } }apiKeyHelper. (<FEAT>/<APP>defaults are in "Inputs to collect" above.) - Tell the admin to fully restart the agent (
claudefor the reference agent) — settings and the API-key helper load at startup only.
Capturing as a runbook (when asked to document, not apply)
If the user wants the setup written up for review instead of applied to their
machine (e.g. "save it as a Markdown runbook"), write all of the above into
the requested file (e.g. models-api-setup-runbook.md), in order and self-contained:
the exact .orgjwt.env contents, the chmod 600 + gitignore note, the
verification curl (with the "must be 200 before writing settings" note), the
full settings.json block with every key from Step 3, and the final
"fully restart claude" step. Don't omit any of the nine settings.json keys.
Verify before finishing
-
.claude/.orgjwt.envcreated,chmod 600, and gitignored - Verification curl returned HTTP
200beforesettings.jsonwas written -
ANTHROPIC_AUTH_TOKENset to""insettings.json -
CLAUDE_CODE_USE_BEDROCKset to"1" -
CLAUDE_CODE_SKIP_BEDROCK_AUTHset to"1" -
ANTHROPIC_BEDROCK_BASE_URLis exactlyhttps://api.salesforce.com/ai/gpt/v1(no trailing slash/path) -
model,ANTHROPIC_DEFAULT_MODEL, andANTHROPIC_SMALL_FAST_MODELall use the fully qualifiedsfdc_ai__…alias -
ANTHROPIC_CUSTOM_HEADERScontainsx-client-feature-idandx-sfdc-app-context -
apiKeyHelperuses absolute paths (bash <SKILL>/scripts/get-orgjwt.sh <ABS>/.claude/.orgjwt.env) - User told to fully restart
claude
Must be exact (each prevents a specific failure)
"ANTHROPIC_AUTH_TOKEN": ""— clears any global token that would otherwise outrankapiKeyHelper(precedence:ANTHROPIC_AUTH_TOKEN>ANTHROPIC_API_KEYapiKeyHelper). Without it → wrong/old bearer → 401/404.CLAUDE_CODE_USE_BEDROCK=1— activates the Bedrock API client; without it Claude Code uses the standard Anthropic API protocol and ignoresANTHROPIC_BEDROCK_BASE_URLentirely, so every call bypasses the Models API.CLAUDE_CODE_SKIP_BEDROCK_AUTH=1— else Claude Code overwritesAuthorizationwith AWS SigV4 and the OrgJWT never lands.apiKeyHelpermust be invoked asbash <path> <credsfile>(avoids exit-126).- Model must be a fully qualified
sfdc_ai__…name (see supported models). - Auth is the OrgJWT from
client_credentials(a signed JWT, 2 dots, scopesfap_api) — NOTsf org display(unsigned session token → 404).sfCLI has no client_credentials command; the helper calls/services/oauth2/token. - Only
ANTHROPIC_BEDROCK_BASE_URLroutes; no tenant-id header needed.
Diagnose
| Error | Meaning | Check first |
|---|---|---|
401 | Token is not a valid OrgJWT | Connected App sfap_api scope, client_credentials flow enabled, consumer key/secret in .orgjwt.env; ANTHROPIC_AUTH_TOKEN not cleared to "" |
404 | Token valid but model/env/org not routable | Fully qualified sfdc_ai__… model alias, ANTHROPIC_BEDROCK_BASE_URL exactly https://api.salesforce.com/ai/gpt/v1, org entitled for the Models API, ANTHROPIC_AUTH_TOKEN cleared |
model not available | Non-alias model id | Replace with a fully qualified sfdc_ai__… alias (see supported models) |
Related skills
More from forcedotcom/sf-skills and the wider catalog.

platform-permission-set-generate
Generate correct, deployable Salesforce permission set metadata with object, field, and user permissions.

platform-policy-rule-generate
Author Salesforce Data Cloud PolicyRuleDefinition and PolicyRuleDefinitionSet metadata XML for governance policies.

platform-quick-deploy
Deploy validated Salesforce metadata to Production without re-running tests.

platform-report-generate
Generate and validate Salesforce Lightning Report metadata (.report-meta.xml) for tabular, summary, matrix, and joined reports.

platform-sandbox-configure
Manage Salesforce sandbox lifecycle—create, refresh, activate, and delete sandboxes via Connect REST API.

platform-sharing-owd-configure
Retrieve and update Organization-Wide Default (OWD) sharing settings for Salesforce objects.